{
  "data": {
    "category": {
      "area": "communication",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync"
      ],
      "description": "APIs that let an agent work in a mailbox a person already has. Searching and reading mail, writing drafts, sending and filing. The mailbox providers' own APIs and services that put one API over several providers. Compared on scopes, search, sync and send limits.",
      "json": "https://www.anchorterminal.com/categories/mailbox-access.json",
      "name": "Mailbox access",
      "slug": "mailbox-access",
      "test": "One test mailbox with the same two hundred messages on each provider. The same tasks run through each listing's API (search, read a thread, write a draft reply, send, label and archive, receive a new-mail event). We check scopes, sync delay and limits. In this run listings are graded from public evidence against the published checklist.",
      "title": "Mailbox access APIs for AI agents",
      "toolCount": 9,
      "tools": [
        "nylas-email",
        "gmail-api",
        "emailengine",
        "outlook-mail-graph",
        "himalaya",
        "unipile",
        "fastmail",
        "zoho-mail",
        "aurinko-email"
      ],
      "url": "https://www.anchorterminal.com/categories/mailbox-access"
    },
    "tools": [
      {
        "slug": "nylas-email",
        "name": "Nylas Email API",
        "vendor": "Nylas",
        "vendorUrl": "https://www.nylas.com",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Unified email API from Nylas for reading, searching, drafting and sending mail in a person's existing Gmail, Microsoft 365, Exchange, Yahoo, iCloud or IMAP mailbox, with webhooks for new mail. A hosted MCP server exposes the same data.",
        "url": "https://www.anchorterminal.com/tools/nylas-email",
        "markdownUrl": "https://www.anchorterminal.com/tools/nylas-email.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nylas-email.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nylas-email.json",
        "repo": "https://github.com/nylas/nylas-nodejs",
        "license": "Proprietary service under Nylas's terms. The SDKs are MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.us.nylas.com/v3",
        "packages": [
          {
            "registry": "npm",
            "name": "nylas"
          },
          {
            "registry": "pypi",
            "name": "nylas"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve. Sign in to the Dashboard or run `nylas init` (Google, Microsoft or GitHub SSO in a browser), then create an API key and send it as a Bearer token. Each mailbox is a grant, created when its owner completes Nylas hosted OAuth, and addressed as /v3/grants/\u003cgrant_id\u003e. Production Google and Microsoft connections need the integrator's own OAuth app as a connector. The application API key reaches every grant. IAM API keys, created in the Dashboard, are limited to one grant, workspace or application and to chosen permissions. The hosted MCP takes either key in the `Authorization` header.",
        "pricing": "freemium",
        "pricingNotes": "Free $0 with 5 email and calendar connected accounts and no card, so an agent's operator can start without a contract. Essentials $15 a month with 10 accounts, then $2.25 each. Pro $49 a month, or $43 billed annually, with 25 accounts, then $2.00 or $1.75 each. Enterprise is custom with volume bands, a HIPAA BAA and an uptime SLA. No per-call charge (https://www.nylas.com/pricing/, checked 2026-10-08).",
        "priceSummary": "$15 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in llms.txt, the OpenAPI spec or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 38,
        "popularity": {
          "githubStars": 181,
          "npmWeekly": 289344,
          "pypiWeekly": 90308,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developer.nylas.com/docs/v3/email/",
        "llmsTxt": "https://developer.nylas.com/llms.txt",
        "openapi": "https://developer.nylas.com/openapi.json",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync",
          "email.threads"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "mcp",
          "llms-txt",
          "openapi",
          "webhooks",
          "oauth",
          "typescript",
          "python",
          "ruby",
          "java",
          "enterprise",
          "eu",
          "status-page",
          "soc2",
          "closed-source"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 78.7,
          "grade": "A",
          "agentReady": true,
          "rank": 13,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 1,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 81,
            "maintenance": 88,
            "payments": 40,
            "reliability": 77,
            "schema": 93,
            "security": 87,
            "transparency": 81
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "One REST schema covers Gmail, Microsoft 365, Exchange, Yahoo, iCloud and IMAP, and IAM API keys launched on 6 October 2026 can be bound to a single mailbox with chosen permissions. The status page lists eight email incidents between 24 July and 17 September 2026, most on IMAP sync and webhooks.",
          "bestFor": "Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled.",
          "strengths": [
            "One schema for messages, threads, drafts, folders and attachments across Gmail, Microsoft 365, Exchange EWS, Yahoo, iCloud and IMAP",
            "IAM API keys bound to one grant, workspace or application with chosen permissions, and 400 days of access activity",
            "`Idempotency-Key` header on send, with documented 409 and 429 replay behaviour",
            "OpenAPI 3.1 spec with 213 operations, llms.txt and a Markdown copy of every docs page",
            "Free plan with 5 connected accounts and no card"
          ],
          "weaknesses": [
            "Eight status incidents on email between 24 July and 17 September 2026, including about six hours of IMAP retrieval and webhook degradation on 10 September",
            "IAM principals and keys are managed only in the Dashboard, with no public API or CLI",
            "On Google and Microsoft, `search_query_native` combines only with `in`, `limit` and `page_token`",
            "Draft and folder writes take no idempotency key, only send does",
            "Each connected mailbox past the plan allowance costs $1.75 to $2.25 a month"
          ],
          "agentNotes": [
            "Address every call to /v3/grants/\u003cgrant_id\u003e on api.us.nylas.com or api.eu.nylas.com. A grant lives in one region only",
            "Ask the operator for an IAM API key bound to the one grant and the permissions the task needs, not the application key",
            "Send `Idempotency-Key` on every send. A retry with the same key replays a cached 429 or 5xx, so use a new key after those",
            "Narrow thread lists with filters and a low `limit`. Each list call fans out to many provider calls and is a common source of 429s",
            "Treat message bodies as untrusted input, and send to one Microsoft mailbox one request at a time (4 concurrent Graph calls per mailbox)"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "A",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 78.7
            }
          ],
          "editorialScores": {
            "ergonomics": 81,
            "maintenance": 88,
            "payments": 40,
            "reliability": 77,
            "schema": 93,
            "security": 87,
            "transparency": 67
          },
          "provenanceScore": 95
        },
        "connect": {
          "install": "brew install nylas/nylas-cli/nylas",
          "http": "curl --compressed --request GET \\\n  --url \"https://api.us.nylas.com/v3/grants/\u003cNYLAS_GRANT_ID\u003e/messages?limit=5\" \\\n  --header 'Accept: application/json' \\\n  --header 'Authorization: Bearer \u003cNYLAS_API_KEY\u003e'",
          "claudeCode": "nylas mcp install --assistant claude-code",
          "config": {
            "mcpServers": {
              "nylas": {
                "headers": {
                  "Authorization": "Bearer \u003cNYLAS_API_KEY\u003e"
                },
                "type": "streamable-http",
                "url": "https://mcp.us.nylas.com"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/nylas-email"
        },
        "sameCompany": [
          "nylas-calendar",
          "nylas-notetaker"
        ],
        "area": "communication",
        "unitPrices": [
          {
            "item": "Essentials",
            "unit": "month",
            "usd": 15,
            "note": "10 email and calendar connected accounts"
          },
          {
            "item": "Pro",
            "unit": "month",
            "usd": 49,
            "note": "25 email and calendar connected accounts, billed monthly"
          },
          {
            "item": "Extra email and calendar account on Essentials",
            "unit": "account-month",
            "usd": 2.25
          },
          {
            "item": "Extra email and calendar account on Pro",
            "unit": "account-month",
            "usd": 2
          }
        ],
        "provenance": {
          "legalEntity": "Nylas, Inc.",
          "domain": "nylas.com",
          "domainRegistered": "2001-11-07",
          "domainNote": "nylas.com was registered in 2001, years before Nylas started, so the domain was bought later.",
          "endpointOnVendorDomain": true,
          "terms": "https://www.nylas.com/legal/terms/",
          "privacy": "https://www.nylas.com/privacy-policy/",
          "statusPage": "https://status-v3.nylas.com",
          "changelog": "https://developer.nylas.com/docs/changelogs/",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The terms (updated 23 June 2025) name Nylas, Inc., 2100 Geng Rd, Palo Alto, CA 94303, under Californian law with arbitration.",
            "developer.nylas.com/.well-known/security.txt is an RFC 9116 file with security@nylas.com as contact, expiring on 1 August 2027. www.nylas.com/.well-known/security.txt returns 404.",
            "The API answers at api.us.nylas.com and api.eu.nylas.com, and the status page for the v3 API is status-v3.nylas.com.",
            "RDAP for nylas.com gives a registration date of 2001-11-07.",
            "The privacy policy was last updated on 6 January 2026 and the sub-processor page on 28 August 2026."
          ],
          "score": 95
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/nylas-email.json",
        "live": {
          "slug": "nylas-email",
          "probe": {
            "target": "https://api.us.nylas.com/v3",
            "method": "get",
            "lastAt": "2026-10-09T22:46:09.160203196Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 129,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 134,
            "p95ms24h": 178,
            "samples24h": 251,
            "samples30d": 331,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 93,
                "ok": 93
              },
              {
                "date": "2026-10-09",
                "probes": 238,
                "ok": 238
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status-v3.nylas.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-09T22:39:10.207262277Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "nylas/nylas-nodejs",
              "version": "v8.4.0",
              "released": "2026-06-24",
              "seenAt": "2026-10-09T17:09:10.402779698Z"
            },
            {
              "registry": "npm",
              "name": "nylas",
              "version": "8.4.0",
              "seenAt": "2026-10-09T17:09:10.231253522Z"
            },
            {
              "registry": "pypi",
              "name": "nylas",
              "version": "6.18.0",
              "released": "2026-09-30",
              "seenAt": "2026-10-09T17:09:10.285487246Z"
            }
          ],
          "githubStars": 181,
          "npmWeekly": 236813,
          "pypiWeekly": 91817,
          "securityTxt": {
            "url": "https://nylas.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-09T15:39:38.199931437Z"
          },
          "llmsTxt": {
            "url": "https://developer.nylas.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-09T14:02:30.801745425Z"
          },
          "updatedAt": "2026-10-09T22:46:09.160203196Z"
        }
      },
      {
        "slug": "gmail-api",
        "name": "Gmail API",
        "vendor": "Google",
        "vendorUrl": "https://developers.google.com/workspace/gmail",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Google's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0.",
        "url": "https://www.anchorterminal.com/tools/gmail-api",
        "markdownUrl": "https://www.anchorterminal.com/tools/gmail-api.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gmail-api.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gmail-api.json",
        "repo": "https://github.com/googleapis/google-api-nodejs-client",
        "license": "Apache-2.0 (client libraries)",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://gmail.googleapis.com/gmail/v1",
        "packages": [
          {
            "registry": "npm",
            "name": "@googleapis/gmail"
          },
          {
            "registry": "pypi",
            "name": "google-api-python-client"
          }
        ],
        "auth": "oauth",
        "authNotes": "OAuth 2.0 access token as a Bearer header, from a Google Cloud project with the Gmail API enabled and an OAuth consent screen. Self-serve for personal use, testing and apps internal to one Workspace organisation. A public app that requests any of the eight restricted scopes, which include `gmail.readonly` and `gmail.metadata`, needs Google's restricted-scope verification, and a CASA security assessment every 12 months if it reaches the data from or through a server. Workspace domains can use a service account with domain-wide delegation. The MCP server needs your own OAuth client ID and secret, the `gmail.readonly` and `gmail.compose` scopes, and Developer Preview Programme membership.",
        "pricing": "free",
        "pricingNotes": "All standard use is at no extra cost, and a free Google account and Cloud project are enough to start, with no card or contract. Limits are 1,200,000 quota units a minute per project, 6,000 a minute per user and a daily threshold of 80,000,000 units per project. Google says use above the daily threshold is planned to be charged to the Cloud billing account later in 2026, with details and at least 90 days' notice still to come (https://developers.google.com/workspace/gmail/api/reference/quota). A security assessment for restricted scopes is paid to a third-party assessor, at a cost Google's pages don't state.",
        "priceSummary": "Free",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Gmail API guides, the quota page or the discovery document (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 23,
        "popularity": {
          "githubStars": 12262,
          "npmWeekly": 1091106,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developers.google.com/workspace/gmail/api/guides",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "tags": [
          "hosted",
          "official",
          "free-tier",
          "mcp",
          "webhooks",
          "oauth",
          "typescript",
          "python",
          "enterprise"
        ],
        "lastRelease": "2026-09-23",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 77.8,
          "grade": "BB",
          "agentReady": true,
          "rank": 19,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 2,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 82,
            "maintenance": 85,
            "payments": 35,
            "reliability": 90,
            "schema": 82,
            "security": 81,
            "transparency": 82
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.",
          "bestFor": "An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.",
          "strengths": [
            "14 OAuth scopes, with `gmail.labels` non-sensitive, `gmail.send` sensitive and permanent delete reserved for the full `https://mail.google.com/` scope",
            "Quota published per method, 5 units for `messages.list`, 20 for `messages.get` and 100 for `messages.send`, against 6,000 units a minute per user",
            "`history.list` and Pub/Sub push notifications give incremental sync from a stored `historyId`",
            "`format=metadata`, `metadataHeaders`, `maxResults` and `fields` keep responses small",
            "No charge for standard use, up to 80,000,000 quota units a day per project"
          ],
          "weaknesses": [
            "Eight restricted scopes, including `gmail.readonly` and `gmail.metadata`, need restricted-scope verification for a public app",
            "An app that stores or transmits restricted data on servers needs a security assessment by a Google-approved assessor every 12 months",
            "No idempotency key on `messages.send`, and the error guide says a 200 response doesn't confirm the mail was sent",
            "MCP server limited to the Developer Preview Programme, with no send tool",
            "Price for use above the daily quota not yet published"
          ],
          "agentNotes": [
            "Ask for the narrowest scope. `gmail.labels` is non-sensitive and `gmail.send` is sensitive, while every scope that reads mail is restricted",
            "List with `messages.list` and `q` in Gmail search syntax, then fetch each ID with `format=metadata` or `full`. List calls return IDs only",
            "Send by posting an RFC 2822 message, base64url encoded, in `raw`. Set `threadId` and matching reply headers to stay in a thread",
            "Store the `historyId` and call `history.list`. On a 404, run a full sync. Call `watch` again at least every 7 days",
            "Back off exponentially on 403 and 429 rate errors, and keep batches to 50 requests or fewer"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 77.8
            }
          ],
          "editorialScores": {
            "ergonomics": 82,
            "maintenance": 85,
            "payments": 35,
            "reliability": 90,
            "schema": 82,
            "security": 81,
            "transparency": 69
          },
          "provenanceScore": 94
        },
        "connect": {
          "http": "curl \"https://gmail.googleapis.com/gmail/v1/users/me/messages?q=is:unread\u0026maxResults=5\" \\\n  -H \"Authorization: Bearer $GOOGLE_ACCESS_TOKEN\"",
          "config": {
            "mcpServers": {
              "gmail": {
                "oauth": {
                  "clientId": "OAUTH_CLIENT_ID",
                  "clientSecret": "OAUTH_CLIENT_SECRET"
                },
                "serverUrl": "https://gmailmcp.googleapis.com/mcp/v1"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/gmail-api"
        },
        "sameCompany": [
          "gemini-api",
          "gemini-embedding",
          "vertex-ai-tuning",
          "google-model-armor",
          "google-imagen",
          "google-veo",
          "google-lyria",
          "google-speech-to-text",
          "gemini-live",
          "google-adk",
          "google-secret-manager",
          "google-cloud-document-ai",
          "google-weather-api",
          "chrome-devtools-mcp",
          "google-maps-platform",
          "google-cloud-translation",
          "google-calendar-api",
          "firebase-cloud-messaging",
          "google-drive-api",
          "gemini-cli",
          "google-search-console",
          "google-ads-api",
          "google-forms",
          "google-sheets-api"
        ],
        "area": "communication",
        "provenance": {
          "legalEntity": "Google LLC",
          "domain": "google.com",
          "domainRegistered": "1997-09-15",
          "domainNote": "The endpoint is on gmail.googleapis.com, Google's API domain. google.com was registered in 1997.",
          "endpointOnVendorDomain": true,
          "terms": "https://developers.google.com/terms",
          "privacy": "https://policies.google.com/privacy",
          "statusPage": "https://www.google.com/appsstatus/dashboard/",
          "changelog": "https://developers.google.com/workspace/gmail/release-notes",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The Google APIs Terms of Service (last modified 9 November 2021) name Google LLC, 1600 Amphitheatre Parkway, Mountain View.",
            "RDAP for google.com gives a registration date of 1997-09-15.",
            "www.google.com/.well-known/security.txt expires on 1 April 2030 and lists a contact, an encryption key and the vulnerability reward policy.",
            "The quota and scopes pages were last updated on 10 September 2026, the MCP setup guide on 18 September and the MCP reference on 21 July.",
            "Google publishes a discovery document for the API, not an OpenAPI spec.",
            "The Workspace status dashboard tracks the Gmail product, not the API on its own."
          ],
          "score": 94
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/gmail-api.json",
        "live": {
          "slug": "gmail-api",
          "probe": {
            "target": "https://gmail.googleapis.com/gmail/v1",
            "method": "get",
            "lastAt": "2026-10-09T22:46:00.397588433Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 66,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 37,
            "p95ms24h": 86,
            "samples24h": 251,
            "samples30d": 331,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 93,
                "ok": 93
              },
              {
                "date": "2026-10-09",
                "probes": 238,
                "ok": 238
              }
            ]
          },
          "vendorStatus": {
            "page": "https://www.google.com/appsstatus/dashboard",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-09T21:19:06.276695172Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "googleapis/google-api-nodejs-client",
              "version": "workspaceevents-v17.0.0",
              "released": "2026-10-08",
              "seenAt": "2026-10-09T16:55:11.880993418Z"
            },
            {
              "registry": "npm",
              "name": "@googleapis/gmail",
              "version": "22.0.1",
              "seenAt": "2026-10-09T16:55:10.879608242Z"
            },
            {
              "registry": "pypi",
              "name": "google-api-python-client",
              "version": "2.201.0",
              "released": "2026-09-30",
              "seenAt": "2026-10-09T16:55:11.728627007Z"
            }
          ],
          "githubStars": 12266,
          "npmWeekly": 876516,
          "pypiWeekly": 31366337,
          "securityTxt": {
            "url": "https://google.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2030-04-01T00:00:00z",
            "checkedAt": "2026-10-09T15:39:28.443612679Z"
          },
          "pages": [
            {
              "url": "https://developers.google.com/workspace/gmail/release-notes",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-09T18:36:05.421734208Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "4656378123eb"
            },
            {
              "url": "https://developers.google.com/terms",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:49.55137795Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "2eb11136bf24"
            }
          ],
          "updatedAt": "2026-10-09T22:46:00.397588433Z"
        }
      },
      {
        "slug": "emailengine",
        "name": "EmailEngine",
        "vendor": "Postal Systems OÜ",
        "vendorUrl": "https://emailengine.app",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "EmailEngine is self-hosted software from Postal Systems that puts one REST API over Gmail, Microsoft 365 and IMAP mailboxes, with webhooks for new mail and a beta MCP server. The owner runs it with Redis.",
        "url": "https://www.anchorterminal.com/tools/emailengine",
        "markdownUrl": "https://www.anchorterminal.com/tools/emailengine.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/emailengine.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/emailengine.json",
        "repo": "https://github.com/postalsys/emailengine",
        "license": "Source available under the EmailEngine licence agreement, version 2.1 of 17 October 2023. Not open source. The PHP SDK is MIT",
        "transports": [
          "http"
        ],
        "packages": [
          {
            "registry": "npm",
            "name": "emailengine-app"
          },
          {
            "registry": "oci",
            "name": "postalsys/emailengine"
          },
          {
            "registry": "packagist",
            "name": "postalsys/emailengine-php"
          }
        ],
        "auth": "api-key",
        "authNotes": "Access is granted by whoever runs the instance, with no vendor approval or app review. Every request takes a 64-character token as `Authorization: Bearer`, or in the `access_token` query parameter. Tokens are created in the admin interface, with the CLI (`emailengine tokens issue`) or through POST /v1/tokens, which only mints tokens bound to one account or narrowed by a permissions record. A token carries scopes (`*`, api, metrics, smtp, imap-proxy, mcp, mcp-manage), an optional account binding, allowlists of actions (read, write, send, destructive) and groups, an IP allowlist, an expiry and a rate limit. The beta MCP endpoint also has an optional built-in OAuth 2.1 server. Mailboxes are connected with the operator's own Google and Microsoft OAuth2 apps, service accounts or IMAP passwords, which stay inside the instance.",
        "pricing": "paid",
        "pricingNotes": "$1,450 or EUR 1,200 a year, excluding VAT, for unlimited mailboxes, instances and API calls, bought with an account at postalsys.com. Every install can start a 14-day trial with full functionality from its own dashboard, with no sign-up and no card, so an agent's owner can start without a contract. When the trial ends the instance stops processing accounts until a licence key is added. A perpetual licence is sold through sales with no public price. The owner also pays for the server and Redis (https://emailengine.app/, https://postalsys.com/plans, checked 2026-10-08).",
        "priceSummary": "$120.83 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 on emailengine.app, in the documentation or in the OpenAPI spec (checked 2026-10-08). Licences are bought by card at postalsys.com, with Stripe named as the payment processor.",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 2237,
          "npmWeekly": 388,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://learn.emailengine.app/",
        "llmsTxt": "https://emailengine.app/llms.txt",
        "openapi": "https://go.emailengine.app/swagger.json",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "tags": [
          "self-hosted",
          "source-available",
          "paid",
          "trial",
          "api-key",
          "openapi",
          "llms-txt",
          "mcp",
          "webhooks",
          "imap",
          "gmail",
          "microsoft-365",
          "docker",
          "nodejs",
          "php"
        ],
        "lastRelease": "2026-10-05",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 71.4,
          "grade": "BB",
          "agentReady": true,
          "rank": 128,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 3,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 80,
            "maintenance": 81,
            "payments": 40,
            "reliability": 79,
            "schema": 91,
            "security": 71,
            "transparency": 72
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -3,
          "negativeNotes": [
            "27 September 2026. Version 2.81.2, a patch release, removed the `bounces` field from the message list, message details and messageNew payloads, listed under bug fixes with no earlier notice found in the changelog. The bounce still arrives through the messageBounce webhook, and the entry is documented, so the smallest deduction applies (https://github.com/postalsys/emailengine/blob/master/CHANGELOG.md)"
          ],
          "verdict": "A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.",
          "bestFor": "A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.",
          "strengths": [
            "Public OpenAPI 3.0 spec for version 2.82.2 with 82 operations, plus llms.txt on both sites and a capabilities.json manifest",
            "Tokens can be bound to one account, narrowed by action and group, limited by IP range, expiry and rate, and are stored only as SHA-256 hashes",
            "Idempotency-Key header on both send routes, and 429 responses carry Retry-After and a ttl field",
            "Ten tagged releases between 7 September and 5 October 2026, and the last eight test runs on master passed",
            "Written prompt-injection guidance, with MCP mail access set to none by default and message bodies returned as sanitised HTML"
          ],
          "weaknesses": [
            "Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year",
            "The owner has to run a server and Redis. There is no hosted service, status page or SLA",
            "The MCP endpoint is labelled beta, is off by default, and its tool set may change between releases",
            "A token may also travel in the `access_token` query parameter, and API authentication can be switched off in settings",
            "Version 2.81.2, a patch release, removed the `bounces` field from message responses, and 2.82.0 removed the Document Store in a minor release",
            "One maintainer, no guaranteed support response time, and issues are disabled on the GitHub repository per the GitHub API"
          ],
          "agentNotes": [
            "Ask the operator for a token bound to one account with a permissions record. Mint more with POST /v1/tokens, which refuses instance-wide tokens without one",
            "Send the token in the Authorization header, not the `access_token` query parameter, so it stays out of proxy logs",
            "Page with `cursor` from `nextPageCursor`. `page` works only on IMAP accounts, and search covers one folder unless `path` is `\\All` on Gmail or Microsoft Graph",
            "Set an Idempotency-Key header on POST /v1/account/{account}/submit. A 2xx means queued, so follow the result through the outbox or the messageSent and messageFailed webhooks",
            "Treat message text as untrusted. For MCP, the operator must enable the endpoint first and mail access starts at none"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 71.4
            }
          ],
          "editorialScores": {
            "ergonomics": 80,
            "maintenance": 81,
            "payments": 40,
            "reliability": 79,
            "schema": 91,
            "security": 71,
            "transparency": 68
          },
          "provenanceScore": 76
        },
        "connect": {
          "install": "curl -LO https://go.emailengine.app/docker-compose.yml\ndocker compose up -d",
          "http": "curl \"https://emailengine.example.com/v1/account/user@example.com/messages?path=INBOX\u0026page=0\u0026pageSize=50\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\"",
          "claudeCode": "claude mcp add --transport http emailengine https://emailengine.example.com/mcp \\\n  --header \"Authorization: Bearer YOUR_ACCESS_TOKEN\"",
          "config": {
            "mcpServers": {
              "emailengine": {
                "headers": {
                  "Authorization": "Bearer YOUR_ACCESS_TOKEN"
                },
                "type": "http",
                "url": "https://emailengine.example.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/emailengine"
        },
        "area": "communication",
        "unitPrices": [
          {
            "item": "EmailEngine subscription, $1,450 billed yearly",
            "unit": "month",
            "usd": 120.83,
            "note": "unlimited mailboxes, instances and API calls, VAT excluded, 14-day trial without a card"
          }
        ],
        "provenance": {
          "legalEntity": "Postal Systems OÜ, Narva mnt 5, 10117 Tallinn, Estonia, registry code 14971894",
          "domain": "emailengine.app",
          "domainRegistered": "2021-07-28",
          "endpointOnVendorDomain": null,
          "terms": "https://postalsys.com/tos",
          "privacy": "https://emailengine.app/privacy-policy",
          "statusPage": "",
          "changelog": "https://github.com/postalsys/emailengine/blob/master/CHANGELOG.md",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The about page names Postal Systems OÜ at Narva mnt 5, 10117 Tallinn, with registry code 14971894 and VAT number EE102255902, and says the company is run by one person.",
            "RDAP for emailengine.app shows registration on 28 July 2021 through Namecheap.",
            "emailengine.app/.well-known/security.txt is PGP-signed, expires on 1 June 2027 and points to GitHub private advisories and SECURITY.md. postalsys.com has its own security.txt with no Expires field.",
            "The terms of service at postalsys.com/tos are dated 14 May 2020 and cover the subscription. The software licence is the EmailEngine licence agreement, version 2.1 of 17 October 2023, governed by Estonian law.",
            "The privacy policy at emailengine.app/privacy-policy has an effective date of 29 July 2026 and covers the website and the licence account, with Stripe named for payments.",
            "The API runs on the owner's instance, so there is no vendor endpoint and no status page."
          ],
          "score": 76
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/emailengine.json",
        "live": {
          "slug": "emailengine",
          "versions": [
            {
              "registry": "github",
              "name": "postalsys/emailengine",
              "version": "v2.83.1",
              "released": "2026-10-08",
              "seenAt": "2026-10-09T16:51:53.89216043Z"
            },
            {
              "registry": "npm",
              "name": "emailengine-app",
              "version": "2.83.1",
              "seenAt": "2026-10-09T16:51:52.899054872Z"
            }
          ],
          "githubStars": 2238,
          "npmWeekly": 635,
          "securityTxt": {
            "url": "https://emailengine.app/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-06-01T00:00:00.000Z",
            "checkedAt": "2026-10-09T15:39:42.849079277Z"
          },
          "llmsTxt": {
            "url": "https://emailengine.app/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-09T14:01:52.760550973Z"
          },
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/postalsys/emailengine/master/CHANGELOG.md",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-09T18:45:57.369645087Z",
              "changedAt": "2026-10-09T18:45:57.369645087Z",
              "fingerprint": "bad92b1dd95d"
            },
            {
              "url": "https://emailengine.app/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-09T18:39:03.761468001Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "bf031c33ef50"
            },
            {
              "url": "https://postalsys.com/tos",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-09T18:43:42.3890862Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "cb7a76a9cb6a"
            }
          ],
          "updatedAt": "2026-10-09T18:45:57.369645087Z"
        }
      },
      {
        "slug": "outlook-mail-graph",
        "name": "Outlook Mail (Microsoft Graph)",
        "vendor": "Microsoft",
        "vendorUrl": "https://learn.microsoft.com/en-us/graph/api/resources/mail-api-overview",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Mail endpoints of Microsoft Graph for Outlook, Microsoft 365 and Exchange Online mailboxes. An app reads, searches, drafts, sends and files messages over REST with OAuth tokens from Microsoft Entra ID.",
        "url": "https://www.anchorterminal.com/tools/outlook-mail-graph",
        "markdownUrl": "https://www.anchorterminal.com/tools/outlook-mail-graph.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/outlook-mail-graph.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/outlook-mail-graph.json",
        "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
        "license": "MIT (SDKs)",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://graph.microsoft.com/v1.0",
        "packages": [
          {
            "registry": "npm",
            "name": "@microsoft/microsoft-graph-client"
          },
          {
            "registry": "pypi",
            "name": "msgraph-sdk"
          }
        ],
        "auth": "oauth",
        "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. No app review by Microsoft was found for mail permissions. Delegated permissions (Mail.ReadBasic, Mail.Read, Mail.ReadWrite, Mail.Send) act as a signed-in user and need only that user's consent. Application permissions reach every mailbox in a tenant, need admin consent, and can be limited to chosen mailboxes with RBAC for Applications in Exchange Online. Personal Outlook.com accounts work with delegated permissions.",
        "pricing": "byo-plan",
        "pricingNotes": "Mail calls aren't metered. The only metered Graph API is SharePoint and OneDrive `assignSensitivityLabel` at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). A work mailbox needs an Exchange Online or Microsoft 365 licence, and Microsoft's plan price page refused our reader on 8 October 2026. A free personal Outlook.com account lets an agent start without a contract. The Microsoft 365 developer programme sandbox is free only to members who qualify, such as Visual Studio subscribers. The Mail MCP server needs a Microsoft 365 Copilot licence.",
        "priceSummary": "Your plan",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Graph mail reference or the metered API list (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 10,
        "popularity": {
          "githubStars": 835,
          "npmWeekly": 2882852,
          "pypiWeekly": 1578201,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/mail-api-overview",
        "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "tags": [
          "hosted",
          "official",
          "oauth",
          "openapi",
          "webhooks",
          "typescript",
          "python",
          "enterprise"
        ],
        "lastRelease": "2026-10-06",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 66.3,
          "grade": "B",
          "agentReady": false,
          "rank": 296,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 4,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 81,
            "maintenance": 76,
            "payments": 35,
            "reliability": 60,
            "schema": 93,
            "security": 71,
            "transparency": 75
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -4,
          "negativeNotes": [
            "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version bumped to 3.0.8, but on 8 October 2026 npm still serves 3.0.7 from September 2023 and the repository has no published advisory. Exploiting it needs an attacker-influenced URL passed to the client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
          ],
          "verdict": "Delegated permissions split reading without bodies (Mail.ReadBasic), full reading, writing and sending, and delta queries and change notifications keep a local copy in step. sendMail takes no idempotency key and returns 202 before delivery, and each app is held to four concurrent requests per mailbox.",
          "bestFor": "Agents working in Microsoft 365 or Outlook.com mailboxes that need scoped reading, drafting, sending and incremental sync.",
          "strengths": [
            "Mail.ReadBasic reads messages without body, preview or attachments, and Mail.Send is separate from Mail.ReadWrite",
            "Delta queries per folder and change notifications with `missed` and `subscriptionRemoved` lifecycle events",
            "`$select`, `$top` (1 to 1,000, default 10), `bodyPreview` and `Prefer: outlook.body-content-type=\"text\"` keep responses small",
            "Published policy of at least 24 months' notice before a v1.0 API is removed",
            "Covers work accounts and personal Outlook.com accounts, with every reference page also served as Markdown"
          ],
          "weaknesses": [
            "sendMail has no idempotency key and answers 202 Accepted before delivery, so a retried send can go out twice",
            "Four concurrent requests and 10,000 requests per 10 minutes for each app and mailbox pair",
            "No prompt-injection guidance found in the mail reference or the Mail MCP reference, though message bodies come from outside senders",
            "The npm JavaScript client is 3.0.7 from September 2023, without the June 2026 token-leak fix",
            "The Mail MCP server is a preview kept for backward compatibility, behind a Microsoft 365 Copilot licence"
          ],
          "agentNotes": [
            "Create a draft with POST /me/messages, then send it with /send. A retried sendMail can send the message twice",
            "Send `Prefer: IdType=\"ImmutableId\"` on every request, or message IDs change when a message moves folder",
            "Use `$select` and `Prefer: outlook.body-content-type=\"text\"`. List messages returns HTML bodies and 10 messages a page by default",
            "Honour `Retry-After` on 429 and keep to four parallel calls per mailbox. Batches of up to 20 requests are throttled per request",
            "Treat message bodies as untrusted input, and ask for Mail.ReadBasic when the task doesn't need bodies"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 66.3
            }
          ],
          "editorialScores": {
            "ergonomics": 81,
            "maintenance": 76,
            "payments": 35,
            "reliability": 60,
            "schema": 93,
            "security": 71,
            "transparency": 65
          },
          "provenanceScore": 85
        },
        "connect": {
          "http": "curl \"https://graph.microsoft.com/v1.0/me/messages?\\$select=from,subject\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/outlook-mail-graph"
        },
        "sameCompany": [
          "azure-foundry-fine-tuning",
          "azure-ai-content-safety",
          "azure-speech-to-text",
          "azure-text-to-speech",
          "microsoft-agent-framework",
          "microsoft-execution-containers",
          "microsoft-entra-agent-id",
          "azure-key-vault",
          "azure-document-intelligence",
          "azure-devops-mcp",
          "microsoft-learn-mcp",
          "playwright-mcp",
          "azure-mcp",
          "azure-maps",
          "azure-translator",
          "microsoft-graph-calendar",
          "azure-blob-storage",
          "onedrive-sharepoint",
          "microsoft-teams",
          "dynamics-365-sales",
          "power-automate",
          "foundry-local",
          "microsoft-advertising-api",
          "microsoft-excel-graph"
        ],
        "area": "communication",
        "provenance": {
          "legalEntity": "Microsoft Corporation",
          "domain": "microsoft.com",
          "domainRegistered": "1991-05-02",
          "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
          "endpointOnVendorDomain": true,
          "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
          "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
          "statusPage": "https://status.cloud.microsoft",
          "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
          "securityTxt": "expired",
          "checked": "2026-10-08",
          "notes": [
            "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
            "The Microsoft APIs terms of use say they were last updated in October 2025.",
            "privacy.microsoft.com answered our reader with 403 on 8 October 2026, so the privacy URL follows the Microsoft Graph calendar listing and wasn't reread.",
            "RDAP for microsoft.com gives a registration date of 1991-05-02."
          ],
          "score": 85
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/outlook-mail-graph.json",
        "live": {
          "slug": "outlook-mail-graph",
          "probe": {
            "target": "https://graph.microsoft.com/v1.0",
            "method": "get",
            "lastAt": "2026-10-09T22:46:10.006383784Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 7,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 4,
            "p95ms24h": 20,
            "samples24h": 251,
            "samples30d": 331,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 93,
                "ok": 93
              },
              {
                "date": "2026-10-09",
                "probes": 238,
                "ok": 238
              }
            ]
          },
          "versions": [
            {
              "registry": "github",
              "name": "microsoftgraph/msgraph-sdk-javascript",
              "version": "3.0.7",
              "released": "2023-09-19",
              "seenAt": "2026-10-09T17:11:35.702199752Z"
            },
            {
              "registry": "npm",
              "name": "@microsoft/microsoft-graph-client",
              "version": "3.0.7",
              "seenAt": "2026-10-09T17:11:35.299392252Z"
            },
            {
              "registry": "pypi",
              "name": "msgraph-sdk",
              "version": "1.64.0",
              "released": "2026-10-06",
              "seenAt": "2026-10-09T17:11:35.586402129Z"
            }
          ],
          "githubStars": 836,
          "npmWeekly": 2346460,
          "pypiWeekly": 1617170,
          "securityTxt": {
            "url": "https://microsoft.com/.well-known/security.txt",
            "state": "expired",
            "expires": "2026-09-23T16:00:00.000Z",
            "checkedAt": "2026-10-09T15:40:16.790821018Z"
          },
          "updatedAt": "2026-10-09T22:46:10.006383784Z"
        }
      },
      {
        "slug": "himalaya",
        "name": "Himalaya",
        "vendor": "Pimalaya",
        "vendorUrl": "https://pimalaya.org",
        "kind": "sdk",
        "category": "mailbox-access",
        "summary": "Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.",
        "url": "https://www.anchorterminal.com/tools/himalaya",
        "markdownUrl": "https://www.anchorterminal.com/tools/himalaya.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/himalaya.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/himalaya.json",
        "repo": "https://github.com/pimalaya/himalaya",
        "license": "MIT OR Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "cargo",
            "name": "himalaya"
          }
        ],
        "auth": "mixed",
        "authNotes": "Himalaya issues no credential of its own. It signs in to the mailbox with what the provider accepts, which is an app password or account password over SASL for IMAP and SMTP, a bearer token or basic auth for JMAP, and one OAuth 2.0 bearer token for the Gmail API or Microsoft Graph. Each secret is read from a shell command such as a password manager, or from a raw value in the config file. Version 2 ships no OAuth flow, so tokens come from an external broker such as `ortie` and an OAuth app the owner registers with Google or Microsoft.",
        "pricing": "free",
        "pricingNotes": "Free software with nothing to buy, and the sponsor page states there is no paid tier. An agent can start with the binary and a mailbox credential. Pimalaya sells optional partnerships, from EUR 3,000 a year for email providers and EUR 5,000 for integrators, and describes a EUR 12 a year sign-in service for Gmail and Microsoft 365 as planned and not built (checked 2026-10-09).",
        "priceSummary": "Free · OSS",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the README, the source or pimalaya.org (checked 2026-10-09).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 7412,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-09"
        },
        "docsUrl": "https://github.com/pimalaya/himalaya",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts"
        ],
        "tags": [
          "open-source",
          "local",
          "cli",
          "rust",
          "free",
          "no-card",
          "imap",
          "smtp",
          "jmap",
          "gmail",
          "microsoft-graph",
          "json-output"
        ],
        "lastRelease": "2026-10-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 64.5,
          "grade": "B",
          "agentReady": false,
          "rank": 348,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 5,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 88,
            "payments": 60,
            "reliability": 84,
            "schema": 70,
            "security": 43,
            "transparency": 69
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-09"
          },
          "negative": -3,
          "negativeNotes": [
            "2 October 2026. Until 2.2.1, `message send` passed the `Bcc:` header through SMTP unchanged, so every recipient could see the blind recipients. Issue #747 reported it against 2.1.0 on 12 September 2026, the fix was committed on 26 September and released on 2 October, and the changelog documents it. No security advisory was published. Fixed and documented, so the smaller deduction applies (https://github.com/pimalaya/himalaya/issues/747)"
          ],
          "verdict": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
          "bestFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
          "strengths": [
            "Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox",
            "`himalaya json-schema` prints a JSON Schema for the `--json` output of 90 commands, and `message read --json` returns one designed view on every backend",
            "Secrets come from a shell command such as `pass show`, so a password or token need not sit in the config file",
            "`message delete` moves mail to the trash first, and `message read` leaves flags alone unless `--seen` is passed",
            "Four tagged releases between 26 July and 2 October 2026, three open issues, and CI badges for tests and audit passing on 9 October 2026"
          ],
          "weaknesses": [
            "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)",
            "No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found",
            "SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found",
            "Only two stable error codes exist under `--json`, `body-pending` and `message-too-complex`. Other failures carry free wording",
            "Version 2 ships no OAuth flow, so Gmail and Microsoft accounts need an external token broker and an OAuth app the owner registers"
          ],
          "agentNotes": [
            "Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1",
            "Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags",
            "Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses",
            "Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces",
            "Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 64.5
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 88,
            "payments": 60,
            "reliability": 84,
            "schema": 70,
            "security": 43,
            "transparency": 74
          },
          "provenanceScore": 63
        },
        "connect": {
          "install": "brew install himalaya   # or: curl -sSL https://raw.githubusercontent.com/pimalaya/himalaya/master/install.sh | PREFIX=~/.local sh",
          "headless": {
            "list": "himalaya envelope list --page 2",
            "read": "himalaya message read 42",
            "search": "himalaya envelope search from alice and after 2026-01-01 order by date desc"
          }
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/himalaya"
        },
        "area": "communication",
        "provenance": {
          "legalEntity": "No legal entity found. Copyright Clément DOUIN (soywod)",
          "domain": "pimalaya.org",
          "domainRegistered": "2022-12-21",
          "endpointOnVendorDomain": null,
          "terms": "",
          "privacy": "",
          "statusPage": "",
          "changelog": "https://github.com/pimalaya/himalaya/blob/master/CHANGELOG.md",
          "securityTxt": "none",
          "checked": "2026-10-09",
          "notes": [
            "pimalaya.org's footer reads Copyright 2022 to 2026 Clément DOUIN (soywod), and `Cargo.toml` names the same author. No company or foundation is named on the pages read.",
            "No terms of service or privacy policy was found. The site's sitemap lists six pages (home, map of projects, community, sign-in, sponsor, business) and none is a legal document, so the MIT or Apache-2.0 licence stands in.",
            "pimalaya.org/.well-known/security.txt and /security.txt both return 404. SECURITY.md in the repository lists 2.x as the supported line and gives the public issue tracker for reports.",
            "RDAP for pimalaya.org gives a registration date of 2022-12-21 and OVH sas as registrar.",
            "The software runs on the owner's machine and connects to the owner's mail servers, so no vendor endpoint exists."
          ],
          "score": 63
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/himalaya.json",
        "live": {
          "slug": "himalaya",
          "versions": [
            {
              "registry": "github",
              "name": "pimalaya/himalaya",
              "version": "v2.2.1",
              "released": "2026-10-02",
              "seenAt": "2026-10-09T16:57:44.106760361Z"
            }
          ],
          "githubStars": 7417,
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/pimalaya/himalaya/master/CHANGELOG.md",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-09T18:45:53.201845848Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "cb5190799b74"
            }
          ],
          "updatedAt": "2026-10-09T18:45:53.201845848Z"
        }
      },
      {
        "slug": "unipile",
        "name": "Unipile",
        "vendor": "UNIPILE SAS",
        "vendorUrl": "https://www.unipile.com",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Unipile is a hosted API from Unipile SAS in France that connects to accounts people already have. It reads, searches, sends and files mail in Gmail, Outlook and IMAP mailboxes, and also covers calendars, LinkedIn, WhatsApp, Instagram and Telegram.",
        "url": "https://www.anchorterminal.com/tools/unipile",
        "markdownUrl": "https://www.anchorterminal.com/tools/unipile.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/unipile.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/unipile.json",
        "repo": "https://github.com/unipile/unipile-node-sdk",
        "license": "Proprietary service under Unipile's terms of use. The v1 Node SDK repository and the unipile-mcp repository carry an MIT licence file",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://developer.unipile.com/mcp?branch=v1.0",
        "packages": [
          {
            "registry": "npm",
            "name": "unipile-node-sdk"
          }
        ],
        "auth": "api-key",
        "authNotes": "Self-serve. A person signs up at dashboard.unipile.com, copies the account's DSN (host and port) and generates an access token, which goes in the `X-API-KEY` header. A v1 token reaches every connected account and has no scopes. Mailboxes are connected by the end user through Google or Microsoft OAuth, using an OAuth app the customer registers and has verified, or with IMAP and SMTP credentials. The v2 beta adds keys limited to a Scope of accounts.",
        "pricing": "paid",
        "pricingNotes": "55 dollars (49 euros) a month covers up to 10 connected accounts, then 5.50 dollars an account a month, falling to 3.50 above 5,000. No charge per request or message. A 7-day trial needs no card, and there is no free tier after it. An SLA needs a custom plan (checked 2026-10-08).",
        "priceSummary": "$55 / mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 5,
        "popularity": {
          "githubStars": 48,
          "npmWeekly": 82529,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developer.unipile.com",
        "llmsTxt": "https://developer.unipile.com/llms.txt",
        "openapi": "https://api1.unipile.com/api-json?port=13111",
        "registryName": "com.unipile/unipile-mcp",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync",
          "calendar.read",
          "calendar.write",
          "calendar.webhooks",
          "messaging.whatsapp",
          "messaging.inbound"
        ],
        "tags": [
          "hosted",
          "paid",
          "free-trial",
          "no-card",
          "api-key",
          "openapi",
          "llms-txt",
          "mcp",
          "webhooks",
          "gmail",
          "outlook",
          "imap",
          "calendar",
          "linkedin",
          "whatsapp",
          "typescript",
          "eu",
          "soc2",
          "status-page",
          "closed-source"
        ],
        "lastRelease": "2026-09-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 58.4,
          "grade": "C",
          "agentReady": false,
          "rank": 581,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 6,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 73,
            "maintenance": 59,
            "payments": 40,
            "reliability": 56,
            "schema": 77,
            "security": 37,
            "transparency": 71
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.",
          "bestFor": "A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account.",
          "strengths": [
            "Public OpenAPI 3.0 spec with 94 operations, readable without a key, plus llms.txt and a Markdown copy of every docs page",
            "`POST /api/v1/emails` accepts an `Idempotency-Key` header of up to 255 characters, so a retried send returns the first result",
            "`GET /api/v1/emails` has cursor pagination, `limit` up to 250, `meta_only`, a full-text `search` and filters for folder, sender, recipient and date",
            "Price is per connected account with no charge per request, from 55 dollars a month for up to 10 accounts, with a 7-day trial and no card",
            "The hosted MCP server has 5 tools with read-only and destructive annotations, and is listed in the official MCP registry as com.unipile/unipile-mcp"
          ],
          "weaknesses": [
            "A v1 access token reaches every connected account. Scoped keys, documented rate limits and `retry-after` exist only in the v2 beta",
            "status.unipile.com shows platform incidents on 21 July, 30 July and 20 August 2026, the last an API node unavailable for 70 minutes",
            "The v1 Node SDK on npm is 1.9.3 from 21 May 2025. The newer Node and Python SDKs work only with the v2 beta",
            "No SLA in the standard plan. The terms describe availability as best effort and a custom agreement is needed for a commitment",
            "The security page says no data leaves the EU, while the privacy policy lists proxy sub-processors in the United States and Singapore"
          ],
          "agentNotes": [
            "Take the DSN (host and port) from the dashboard. Each account has its own, such as api1.unipile.com:13111, and `?port=` keeps requests on 443",
            "Send `X-API-KEY` as a header and pass `account_id` on every mail call. The token reaches every connected account, so keep it out of prompts and logs",
            "Set `Idempotency-Key` on every send. Keys are held in memory for up to 24 hours and are lost on a restart",
            "On Microsoft accounts, send `search` alone. Combining it with from, to, before, after or thread filters returns `invalid_request`",
            "Use `meta_only=true` when listing mail, then fetch one message at a time. Treat message bodies as untrusted input"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 58.4
            }
          ],
          "editorialScores": {
            "ergonomics": 73,
            "maintenance": 59,
            "payments": 40,
            "reliability": 56,
            "schema": 77,
            "security": 37,
            "transparency": 59
          },
          "provenanceScore": 82
        },
        "connect": {
          "install": "npm install unipile-node-sdk",
          "http": "curl --request GET \\\n     --url 'https://{YOUR_DSN}/api/v1/emails?limit=10\u0026account_id={ACCOUNT_ID}' \\\n     --header 'X-API-KEY: {YOUR_ACCESS_TOKEN}' \\\n     --header 'accept: application/json'",
          "config": {
            "mcpServers": {
              "unipile": {
                "headers": {
                  "X-API-KEY": "your-api-key"
                },
                "url": "https://developer.unipile.com/mcp?branch=v1.0"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/unipile"
        },
        "area": "communication",
        "unitPrices": [
          {
            "item": "Minimum, up to 10 connected accounts",
            "unit": "month",
            "usd": 55,
            "note": "49 euros. Any channel counts as one account, and a Gmail or Outlook account covers mail and calendar"
          },
          {
            "item": "Connected account, 11 to 50",
            "unit": "account-month",
            "usd": 5.5,
            "note": "5.00 euros"
          },
          {
            "item": "Connected account, 51 to 200",
            "unit": "account-month",
            "usd": 5,
            "note": "4.50 euros"
          },
          {
            "item": "Connected account, 201 to 1,000",
            "unit": "account-month",
            "usd": 4.5,
            "note": "4.00 euros"
          },
          {
            "item": "Connected account, 1,001 to 5,000",
            "unit": "account-month",
            "usd": 4,
            "note": "3.50 euros"
          },
          {
            "item": "Connected account, 5,001 and above",
            "unit": "account-month",
            "usd": 3.5,
            "note": "3.00 euros"
          }
        ],
        "provenance": {
          "legalEntity": "UNIPILE SAS",
          "domain": "unipile.com",
          "domainRegistered": "2020-11-17",
          "endpointOnVendorDomain": true,
          "terms": "https://www.unipile.com/terms-of-use/",
          "privacy": "https://www.unipile.com/privacy-policy/",
          "statusPage": "https://status.unipile.com",
          "changelog": "https://developer.unipile.com/changelog",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The legal notice names UNIPILE SAS, registered with the RCS of Roanne under number 885265595, head office 168 rue de la Rotonde, 42153 Riorges, France.",
            "The API answers on a per-account host and port under unipile.com, such as api1.unipile.com:13111. The MCP server is at developer.unipile.com/mcp, a ReadMe-hosted docs site on the vendor's domain.",
            "www.unipile.com/.well-known/security.txt returns 404. No vulnerability disclosure policy or bug bounty was found on the security page.",
            "The terms are governed by French law, with the Commercial Court of Roanne as the court. They say changes take effect on publication.",
            "RDAP for unipile.com gives a registration date of 2020-11-17."
          ],
          "score": 82
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/unipile.json",
        "live": {
          "slug": "unipile",
          "probe": {
            "target": "https://developer.unipile.com/mcp?branch=v1.0",
            "method": "get",
            "lastAt": "2026-10-09T22:46:21.551782133Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 48,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 49,
            "p95ms24h": 107,
            "samples24h": 251,
            "samples30d": 331,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 93,
                "ok": 93
              },
              {
                "date": "2026-10-09",
                "probes": 238,
                "ok": 238
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.unipile.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-09T21:19:56.398394485Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "unipile/unipile-node-sdk",
              "version": "v1.9.3",
              "released": "2025-05-21",
              "seenAt": "2026-10-09T17:26:03.706854998Z"
            },
            {
              "registry": "mcp-registry",
              "name": "com.unipile/unipile-mcp",
              "version": "1.0.0",
              "seenAt": "2026-10-09T02:57:46.004536428Z"
            },
            {
              "registry": "npm",
              "name": "unipile-node-sdk",
              "version": "1.9.3",
              "seenAt": "2026-10-09T17:26:02.870834Z"
            }
          ],
          "githubStars": 48,
          "npmWeekly": 64458,
          "securityTxt": {
            "url": "https://unipile.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-09T15:40:05.12019111Z"
          },
          "llmsTxt": {
            "url": "https://developer.unipile.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-09T14:02:56.103637016Z"
          },
          "pages": [
            {
              "url": "https://developer.unipile.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-09T18:35:24.694206758Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "14178c9246c1"
            },
            {
              "url": "https://www.unipile.com/privacy-policy/",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-09T18:55:14.013902812Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "cbc48f825ecc"
            },
            {
              "url": "https://www.unipile.com/terms-of-use/",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-09T18:55:16.024548089Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "3d0b4ec6b8b4"
            }
          ],
          "updatedAt": "2026-10-09T22:46:21.551782133Z"
        }
      },
      {
        "slug": "fastmail",
        "name": "Fastmail API (JMAP)",
        "vendor": "Fastmail Pty Ltd",
        "vendorUrl": "https://www.fastmail.com",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Fastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server.",
        "url": "https://www.anchorterminal.com/tools/fastmail",
        "markdownUrl": "https://www.anchorterminal.com/tools/fastmail.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/fastmail.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/fastmail.json",
        "repo": "https://github.com/fastmail/JMAP-Samples",
        "license": "Proprietary service under Fastmail's API Terms of Service and API Developer Policy. JMAP is an open IETF standard, and the sample code on GitHub is MIT",
        "transports": [
          "http"
        ],
        "packages": [],
        "auth": "mixed",
        "authNotes": "Access is self-serve for the account owner. An API token is made in Settings, Privacy \u0026 Security, Manage API tokens, as type JMAP or MCP, with scopes for read-only access, Email, Email submission, Contacts and Masked Email, and is sent as `Authorization: Bearer`. Tokens are not available on Basic plans. An app distributed to other users needs OAuth 2.0 (authorisation code grant, PKCE S256, rotating refresh tokens), and the developer page says clients are registered by hand through the partnerships team. The MCP server takes OAuth or an MCP-type token, and the authorisation server metadata lists a registration endpoint.",
        "pricing": "paid",
        "pricingNotes": "API access is part of a mailbox plan, with no per-call charge. Individual is $6 a month or $60 a year, Business Standard $6 a user a month and Professional $10. Basic, at $4, has no API tokens. A trial of up to 30 days needs no card, so an agent's owner can start without a contract, with sending capped at 120 messages a day (https://www.fastmail.com/pricing/us/, checked 2026-10-08).",
        "priceSummary": "$6 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 on the developer page, the pricing page or the 401 responses from api.fastmail.com (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 123,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://www.fastmail.com/dev/",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "tags": [
          "hosted",
          "paid",
          "trial",
          "jmap",
          "open-standard",
          "oauth",
          "api-key",
          "mcp",
          "email",
          "contacts",
          "masked-email",
          "status-page",
          "bug-bounty",
          "eu-data-residency"
        ],
        "lastRelease": "2026-04-22",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 54.1,
          "grade": "C",
          "agentReady": false,
          "rank": 694,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 7,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 73,
            "maintenance": 26,
            "payments": 30,
            "reliability": 54,
            "schema": 52,
            "security": 60,
            "transparency": 74
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.",
          "bestFor": "An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.",
          "strengths": [
            "JMAP is an IETF standard (RFC 8620, 8621 and 9610), so requests, types and errors are specified in public and not tied to one vendor",
            "API tokens can be read-only or limited to mail, sending, contacts or Masked Email, and are revocable in settings",
            "OAuth 2.0 requires PKCE with S256, rotates refresh tokens on every use and revokes the grant if an old one is replayed",
            "The MCP server at `https://api.fastmail.com/mcp`, launched 22 April 2026, has separate read, write and send levels chosen on the consent screen",
            "`properties`, `limit`, `bodyProperties` and `maxBodyValueBytes` size responses, and several calls batch into one request with back-references",
            "30-day trial with no card, a privacy policy with stated retention periods and a published list of 36 subprocessors"
          ],
          "weaknesses": [
            "The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows",
            "No OpenAPI file, llms.txt, official SDK or API changelog. The developer page points to the RFCs and four sample scripts",
            "No request rate limit, Retry-After guidance or SLA was found, and the API terms allow backwards-incompatible changes with notice only promised as an attempt",
            "Three partial outages between 25 August and 7 October 2026 blocked access for some users for 8 hours 16 minutes, 1 hour 8 minutes and 5 hours 23 minutes",
            "API tokens are not available on Basic plans, and the developer page says OAuth clients are registered by hand through the partnerships team",
            "No idempotency key on `EmailSubmission/set`, no confirmation step for delete or send, and no per-call access log",
            "Fastmail says it has not pursued SOC certification, and no ISO 27001 certificate was found"
          ],
          "agentNotes": [
            "Fetch `https://api.fastmail.com/jmap/session` with `Authorization: Bearer \u003ctoken\u003e` first. It returns the API URL, account IDs and the request limits to stay under",
            "Ask the owner for a read-only token unless the task writes. Sending needs both the Email and Email submission scopes",
            "Request only the `properties` you need. Body text is not returned unless `fetchTextBodyValues` is set, and `maxBodyValueBytes` caps it",
            "Sync with `Email/changes` from a stored state. On `cannotCalculateChanges`, fetch again from scratch",
            "Do not send generated mail to outside recipients without the owner's review. The customer terms forbid it, and trial accounts stop at 120 messages a day"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 54.1
            }
          ],
          "editorialScores": {
            "ergonomics": 73,
            "maintenance": 26,
            "payments": 30,
            "reliability": 54,
            "schema": 52,
            "security": 60,
            "transparency": 62
          },
          "provenanceScore": 86
        },
        "connect": {
          "http": "curl https://api.fastmail.com/jmap/session \\\n  -H \"Authorization: Bearer YOUR_API_TOKEN\""
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/fastmail"
        },
        "area": "communication",
        "unitPrices": [
          {
            "item": "Individual plan, billed monthly",
            "unit": "month",
            "usd": 6,
            "note": "one mailbox, API tokens included, 30-day trial without a card"
          },
          {
            "item": "Individual plan, $60 billed yearly",
            "unit": "month",
            "usd": 5,
            "note": "one mailbox, API tokens included"
          },
          {
            "item": "Business Standard, billed monthly",
            "unit": "seat-month",
            "usd": 6,
            "note": "per user, API tokens included. Basic at $4 has none"
          }
        ],
        "provenance": {
          "legalEntity": "Fastmail Pty Ltd, ACN 142 646 580, PO Box 234, Collins Street West, VIC 8007, Australia",
          "domain": "fastmail.com",
          "domainRegistered": "1994-12-09",
          "endpointOnVendorDomain": true,
          "terms": "https://www.fastmail.com/policies/api-terms-of-service/",
          "privacy": "https://www.fastmail.com/policies/privacy/",
          "statusPage": "https://fastmailstatus.com/",
          "changelog": "",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The privacy policy names Fastmail Pty Ltd with ABN 31 142 646 580, and the terms of service give ACN 142 646 580, both at PO Box 234, Collins Street West, VIC 8007.",
            "RDAP for fastmail.com shows registration on 9 December 1994 and expiry on 8 December 2034.",
            "www.fastmail.com/.well-known/security.txt expires on 24 June 2027 and points to the bug bounty page for contact and policy.",
            "The API Terms of Service and the API Developer Policy together form the contract for API use, governed by the law of Victoria, Australia. The customer Terms of Service, last changed 10 October 2025 per its version list, govern the account the API reaches.",
            "The privacy policy lists versions back to 25 May 2020, the latest dated 2 July 2026.",
            "JMAP, OAuth and MCP all answer on api.fastmail.com. The status page is on fastmailstatus.com, hosted by Instatus.",
            "No API changelog was found."
          ],
          "score": 86
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/fastmail.json",
        "live": {
          "slug": "fastmail",
          "vendorStatus": {
            "page": "https://fastmailstatus.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-09T21:19:02.944096304Z"
          },
          "githubStars": 123,
          "securityTxt": {
            "url": "https://fastmail.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-06-24T00:00:00.000Z",
            "checkedAt": "2026-10-09T15:40:02.699489243Z"
          },
          "pages": [
            {
              "url": "https://www.fastmail.com/pricing/us/",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-09T18:50:06.55208356Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f82655a263b3"
            },
            {
              "url": "https://www.fastmail.com/policies/privacy/",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-09T18:50:04.525742369Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "46e72082b1b3"
            },
            {
              "url": "https://www.fastmail.com/policies/api-terms-of-service/",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-09T18:50:02.423137198Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f73a69f7e8ec"
            }
          ],
          "updatedAt": "2026-10-09T21:19:02.944096304Z"
        }
      },
      {
        "slug": "zoho-mail",
        "name": "Zoho Mail API",
        "vendor": "Zoho",
        "vendorUrl": "https://www.zoho.com/mail/",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Zoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access.",
        "url": "https://www.anchorterminal.com/tools/zoho-mail",
        "markdownUrl": "https://www.anchorterminal.com/tools/zoho-mail.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoho-mail.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoho-mail.json",
        "license": "Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found",
        "transports": [
          "http"
        ],
        "packages": [],
        "auth": "oauth",
        "authNotes": "OAuth 2.0 only. A person registers a client in the Zoho API console (server-based, client-based, mobile, non-browser with device authorisation, or a self client for one's own account) and approves scopes of the form `ZohoMail.\u003cresource\u003e.\u003coperation\u003e`. Registration is self-serve, with no app review or sales approval found. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Organisation calls need an administrator's account. Each data centre has its own accounts host and API host.",
        "pricing": "freemium",
        "pricingNotes": "API access comes with a mailbox plan and has no per-call charge. Mail Free covers up to five users on one domain with no card and is available in some regions only. Paid plans cost $1 to $6 a user a month billed yearly, with a 15-day trial of the highest edition and no card. The API guide says plan and mail policy decide which APIs an account can call (https://www.zoho.com/mail/zohomail-pricing.html, checked 2026-10-09).",
        "priceSummary": "$1 / seat-mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the API guide, the OAuth guide or the pricing page (checked 2026-10-09).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-09"
        },
        "docsUrl": "https://www.zoho.com/mail/help/api/",
        "llmsTxt": "https://www.zoho.com/mail/help/llms.txt",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "tags": [
          "hosted",
          "closed-source",
          "oauth",
          "mcp",
          "webhooks",
          "free-tier",
          "no-card",
          "llms-txt",
          "email",
          "status-page",
          "bug-bounty",
          "soc2",
          "eu-data-residency"
        ],
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 53.8,
          "grade": "D",
          "agentReady": false,
          "rank": 702,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 8,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 56,
            "maintenance": 33,
            "payments": 30,
            "reliability": 63,
            "schema": 45,
            "security": 67,
            "transparency": 73
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-09"
          },
          "negative": 0,
          "verdict": "A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.",
          "bestFor": "An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.",
          "strengths": [
            "OAuth scopes name one resource and one operation, such as `ZohoMail.messages.READ`, so an agent can hold read access without send or delete.",
            "Every reference page has a Markdown twin, indexed in `https://www.zoho.com/mail/help/llms.txt`, with a curl sample and a sample response.",
            "Zoho Mail MCP exposes the API methods as tools on a remote server, and the owner picks which tools a server carries.",
            "The Mail Free plan covers five users on one domain with no card, and the MCP FAQ says free and paid plans both work.",
            "Delete moves a message to Trash unless `expunge=true` is sent, and audit records, login history and SMTP logs are readable through the Logs API."
          ],
          "weaknesses": [
            "The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.",
            "No OpenAPI file, official REST SDK or dated API changelog was found. The path carries no version.",
            "The getting started guide says each API has its own rate limit and gives no numbers. The response code list has no 429.",
            "External sending is capped at 50 to 500 emails an hour by sender reputation, with a block of up to one hour once the cap is reached.",
            "The OAuth guide's token, refresh and revoke examples carry the client secret and refresh token in the URL query string."
          ],
          "agentNotes": [
            "Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e`, not `Bearer`. The token response says `Bearer`, but the OAuth guide says the Mail API requires the Zoho prefix.",
            "Use the host for the account's data centre, such as `mail.zoho.eu` or `mail.zoho.in`. Call `GET /api/accounts` first for the `accountId` every mailbox call needs.",
            "Reading a message body needs both `folderId` and `messageId`. List and search calls return a summary only, 10 messages by default and 200 at most.",
            "Request `ZohoMail.messages.READ` alone for a reading agent. Add `CREATE` only when it must send, and leave `DELETE` out unless required.",
            "Refresh the access token every hour, and post OAuth parameters in the request body where the server accepts it, to keep secrets out of URLs."
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "D",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 53.8
            }
          ],
          "editorialScores": {
            "ergonomics": 56,
            "maintenance": 33,
            "payments": 30,
            "reliability": 63,
            "schema": 45,
            "security": 67,
            "transparency": 51
          },
          "provenanceScore": 95
        },
        "connect": {
          "http": "curl \"https://mail.zoho.com/api/accounts\" \\\n  -X GET \\\n  -H \"Accept: application/json\" \\\n  -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\""
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/zoho-mail"
        },
        "sameCompany": [
          "zoho-books",
          "zoho-zeptomail",
          "zoho-crm",
          "zoho-desk",
          "zoho-recruit",
          "zoho-people"
        ],
        "area": "communication",
        "unitPrices": [
          {
            "item": "Mail Lite, 5 GB",
            "unit": "seat-month",
            "usd": 1,
            "note": "billed yearly, no monthly plan. $1.25 for 10 GB"
          },
          {
            "item": "Workplace Standard",
            "unit": "seat-month",
            "usd": 3,
            "note": "billed yearly. $4 billed monthly. 30 GB mailbox plus the office suite"
          },
          {
            "item": "Mail Premium",
            "unit": "seat-month",
            "usd": 4,
            "note": "billed yearly, no monthly plan. 50 GB mailbox with retention and eDiscovery"
          },
          {
            "item": "Workplace Professional",
            "unit": "seat-month",
            "usd": 6,
            "note": "billed yearly. 100 GB mailbox"
          }
        ],
        "provenance": {
          "legalEntity": "Zoho Corporation Private Limited",
          "domain": "zoho.com",
          "domainRegistered": "2004-01-16",
          "endpointOnVendorDomain": true,
          "terms": "https://www.zoho.com/terms.html",
          "privacy": "https://www.zoho.com/privacy.html",
          "statusPage": "https://status.zoho.com",
          "changelog": "https://www.zoho.com/mail/whats-new.html",
          "securityTxt": "valid",
          "checked": "2026-10-09",
          "notes": [
            "The Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).",
            "The Zoho Mail usage policy at https://www.zoho.com/mail/help/usage-policy.html, last updated 2 September 2026, adds rules for the mail service and bars automated and bulk email.",
            "The privacy policy was last updated on 22 December 2025. Part II covers data Zoho processes on a customer's behalf.",
            "security.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.",
            "What's New is a product changelog dated by month, with the latest entries under August 2026. No API changelog was found.",
            "The US API answers on mail.zoho.com. Other data centres use mail.zoho.eu, mail.zoho.in, mail.zoho.com.au, mail.zoho.jp, mail.zohocloud.ca, mail.zoho.com.cn, mail.zoho.ae and mail.zoho.sa. OAuth runs on accounts.zoho.com.",
            "RDAP for zoho.com gives a registration date of 2004-01-16 and expiry on 2031-01-16."
          ],
          "score": 95
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/zoho-mail.json",
        "live": {
          "slug": "zoho-mail",
          "securityTxt": {
            "url": "https://zoho.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2028-06-30T23:59:59.000Z",
            "checkedAt": "2026-10-09T15:40:32.838784892Z"
          },
          "llmsTxt": {
            "url": "https://www.zoho.com/mail/help/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-09T14:03:05.053121001Z"
          },
          "pages": [
            {
              "url": "https://www.zoho.com/mail/whats-new.html",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-09T18:56:15.852510636Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5dd41bf4a099"
            },
            {
              "url": "https://www.zoho.com/mail/zohomail-pricing.html",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-09T18:56:17.891172142Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0823801268d9"
            }
          ],
          "updatedAt": "2026-10-09T18:56:17.891172142Z"
        }
      },
      {
        "slug": "aurinko-email",
        "name": "Aurinko Email API",
        "vendor": "Yoxel, Inc.",
        "vendorUrl": "https://www.aurinko.io",
        "kind": "http-api",
        "category": "mailbox-access",
        "summary": "Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.",
        "url": "https://www.anchorterminal.com/tools/aurinko-email",
        "markdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aurinko-email.json",
        "license": "Proprietary service under Yoxel's Terms of Services Agreement",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.aurinko.io",
        "packages": [],
        "auth": "oauth",
        "authNotes": "Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each mailbox owner connects through Aurinko's OAuth flow at `/v1/auth/authorize`, and the resulting account access token is sent as a Bearer token. Mail scopes are `Mail.Read`, `Mail.ReadWrite`, `Mail.Send` and `Mail.Drafts`. IMAP, iCloud and Exchange accounts connect with a password or app password. Gmail access needs the developer's own Google OAuth app, since Aurinko's default registration excludes Google email, and production Office 365 needs an Azure registration.",
        "pricing": "paid",
        "pricingNotes": "$1.50 an active account a month for Email (non-IMAP) with up to 1 GB of traffic, and $2 for any number of APIs including IMAP with unlimited traffic, per the billing FAQ. A 14-day trial gives full API access, and requests are blocked when it ends without a card on file. No free tier or sandbox beyond the trial (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs, the OpenAPI description or the pricing page (checked 2026-10-09).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-09"
        },
        "docsUrl": "https://docs.aurinko.io/unified-apis/email-api",
        "llmsTxt": "https://docs.aurinko.io/llms.txt",
        "openapi": "https://apirefs.aurinko.io/assets/swagger.json",
        "capabilities": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync",
          "email.threads"
        ],
        "tags": [
          "hosted",
          "oauth",
          "openapi",
          "llms-txt",
          "webhooks",
          "closed-source",
          "free-trial"
        ],
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 44.2,
          "grade": "E",
          "agentReady": false,
          "rank": 878,
          "ranked": true,
          "rankOf": 950,
          "categoryRank": 9,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 49,
            "maintenance": 13,
            "payments": 40,
            "reliability": 40,
            "schema": 67,
            "security": 42,
            "transparency": 44
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-09"
          },
          "negative": 0,
          "verdict": "One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.",
          "bestFor": "A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.",
          "strengths": [
            "Public OpenAPI 3.0 description at `apirefs.aurinko.io/assets/swagger.json`, with 43 email operations, 34 of them carrying a cURL sample",
            "Four mail scopes. `Mail.Read` allows no writes, `Mail.Send` allows sending with no read access, and `Mail.ReadWrite` excludes send",
            "The `q` parameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial",
            "Prices published per active account a month ($1.50 for email, $2 for all APIs with IMAP), with a 14-day trial",
            "Docs state that message contents are passed through and never stored, with only IDs and thread relations cached for sync"
          ],
          "weaknesses": [
            "No status page, incident history or SLA found, and the terms supply the service as is",
            "No idempotency key on `POST /v1/email/messages`, so a retried send can deliver twice",
            "No changelog, deprecation policy or official SDK found in the docs or on the site",
            "The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password",
            "The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run"
          ],
          "agentNotes": [
            "Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io`",
            "Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first",
            "Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it",
            "Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet",
            "Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "E",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 44.2
            }
          ],
          "editorialScores": {
            "ergonomics": 49,
            "maintenance": 13,
            "payments": 40,
            "reliability": 40,
            "schema": 67,
            "security": 42,
            "transparency": 27
          },
          "provenanceScore": 60
        },
        "connect": {
          "http": "curl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -G https://api.aurinko.io/v1/email/messages \\\n  -d q='from:alexey'"
        },
        "letme": {
          "capability": "https://letme.dev/mailbox.read",
          "tool": "https://letme.dev/aurinko-email"
        },
        "sameCompany": [
          "aurinko-calendar"
        ],
        "area": "communication",
        "unitPrices": [
          {
            "item": "Email API (non-IMAP)",
            "unit": "account-month",
            "usd": 1.5,
            "note": "Per active account, up to 1 GB of traffic a month"
          },
          {
            "item": "Full platform, any number of APIs including IMAP",
            "unit": "account-month",
            "usd": 2,
            "note": "Per active account, unlimited traffic"
          }
        ],
        "provenance": {
          "legalEntity": "Yoxel, Inc.",
          "domain": "aurinko.io",
          "domainRegistered": "2019-05-08",
          "endpointOnVendorDomain": true,
          "terms": "https://www.aurinko.io/terms/",
          "privacy": "https://www.aurinko.io/privacy/",
          "statusPage": "",
          "changelog": "",
          "securityTxt": "none",
          "checked": "2026-10-09",
          "notes": [
            "The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration under JAMS rules in San Francisco, with a 30-day opt-out.",
            "The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.",
            "The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. We read a handful of public pages and sent nothing to the API host.",
            "The API answers at api.aurinko.io per the description file, with the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.",
            "www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.",
            "No status page or changelog is linked from the home page, the docs index or the description file.",
            "robots.txt on www.aurinko.io has one `User-agent: *` line and no rules. On docs.aurinko.io it allows every path with `Content-Signal: ai-input=yes`. apirefs.aurinko.io answered 404 for robots.txt, read as no rules.",
            "RDAP for aurinko.io gives a registration date of 2019-05-08."
          ],
          "score": 60
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/aurinko-email.json",
        "live": {
          "slug": "aurinko-email",
          "probe": {
            "target": "https://api.aurinko.io",
            "method": "get",
            "lastAt": "2026-10-09T22:45:50.270950071Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 152,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 119,
            "p95ms24h": 298,
            "samples24h": 73,
            "samples30d": 73,
            "days": [
              {
                "date": "2026-10-09",
                "probes": 73,
                "ok": 73
              }
            ]
          },
          "updatedAt": "2026-10-09T22:45:50.270950071Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/mailbox-access",
    "json": "https://www.anchorterminal.com/categories/mailbox-access.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/mailbox-access.md",
    "slim": "https://www.anchorterminal.com/categories/mailbox-access.min.md"
  },
  "markdown": "APIs that let an agent work in a mailbox a person already has. Searching and reading mail, writing drafts, sending and filing. The mailbox providers' own APIs and services that put one API over several providers. Compared on scopes, search, sync and send limits.\n\n- Tools ranked: 9 · agent-ready (BB or better): 3 · accept x402: 0 · hosted endpoints: 5 · desk reviews by the panel: 0\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Shortlist and picks by need: https://www.anchorterminal.com/best/mailbox-access/index.md\n- Head-to-head comparisons (36): https://www.anchorterminal.com/compare/mailbox-access/index.md\n- Capabilities in this category: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync\n- https://letme.dev/mailbox.read picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 13 | Nylas Email API | Nylas | HTTP API | Mailboxes | A | 78.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/nylas-email.md |\n| 19 | Gmail API | Google | HTTP API | Mailboxes | BB | 77.8 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/gmail-api.md |\n| 128 | EmailEngine | Postal Systems OÜ | HTTP API | Mailboxes | BB | 71.4 | medium | no | API key | local | none | https://www.anchorterminal.com/tools/emailengine.md |\n| 296 | Outlook Mail (Microsoft Graph) | Microsoft | HTTP API | Mailboxes | B | 66.3 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/outlook-mail-graph.md |\n| 348 | Himalaya | Pimalaya | SDK + MCP | Mailboxes | B | 64.5 | medium | no | OAuth or key | local | none | https://www.anchorterminal.com/tools/himalaya.md |\n| 581 | Unipile | UNIPILE SAS | HTTP API | Mailboxes | C | 58.4 | medium | no | API key | hosted | none | https://www.anchorterminal.com/tools/unipile.md |\n| 694 | Fastmail API (JMAP) | Fastmail Pty Ltd | HTTP API | Mailboxes | C | 54.1 | medium | no | OAuth or key | local | none | https://www.anchorterminal.com/tools/fastmail.md |\n| 702 | Zoho Mail API | Zoho | HTTP API | Mailboxes | D | 53.8 | medium | no | OAuth | local | none | https://www.anchorterminal.com/tools/zoho-mail.md |\n| 878 | Aurinko Email API | Yoxel, Inc. | HTTP API | Mailboxes | E | 44.2 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/aurinko-email.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 13. Nylas Email API, A (78.7)\n\nUnified email API from Nylas for reading, searching, drafting and sending mail in a person's existing Gmail, Microsoft 365, Exchange, Yahoo, iCloud or IMAP mailbox, with webhooks for new mail. A hosted MCP server exposes the same data. One REST schema covers Gmail, Microsoft 365, Exchange, Yahoo, iCloud and IMAP, and IAM API keys launched on 6 October 2026 can be bound to a single mailbox with chosen permissions. The status page lists eight email incidents between 24 July and 17 September 2026, most on IMAP sync and webhooks.\n\n- Page: https://www.anchorterminal.com/tools/nylas-email · Markdown: https://www.anchorterminal.com/tools/nylas-email.md · JSON: https://www.anchorterminal.com/api/v1/tools/nylas-email.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads · endpoint: `https://api.us.nylas.com/v3`\n\n### 19. Gmail API, BB (77.8)\n\nGoogle's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0. Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.\n\n- Page: https://www.anchorterminal.com/tools/gmail-api · Markdown: https://www.anchorterminal.com/tools/gmail-api.md · JSON: https://www.anchorterminal.com/api/v1/tools/gmail-api.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync · endpoint: `https://gmail.googleapis.com/gmail/v1`\n\n### 128. EmailEngine, BB (71.4)\n\nEmailEngine is self-hosted software from Postal Systems that puts one REST API over Gmail, Microsoft 365 and IMAP mailboxes, with webhooks for new mail and a beta MCP server. The owner runs it with Redis. A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.\n\n- Page: https://www.anchorterminal.com/tools/emailengine · Markdown: https://www.anchorterminal.com/tools/emailengine.md · JSON: https://www.anchorterminal.com/api/v1/tools/emailengine.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync\n\n### 296. Outlook Mail (Microsoft Graph), B (66.3)\n\nMail endpoints of Microsoft Graph for Outlook, Microsoft 365 and Exchange Online mailboxes. An app reads, searches, drafts, sends and files messages over REST with OAuth tokens from Microsoft Entra ID. Delegated permissions split reading without bodies (Mail.ReadBasic), full reading, writing and sending, and delta queries and change notifications keep a local copy in step. sendMail takes no idempotency key and returns 202 before delivery, and each app is held to four concurrent requests per mailbox.\n\n- Page: https://www.anchorterminal.com/tools/outlook-mail-graph · Markdown: https://www.anchorterminal.com/tools/outlook-mail-graph.md · JSON: https://www.anchorterminal.com/api/v1/tools/outlook-mail-graph.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync · endpoint: `https://graph.microsoft.com/v1.0`\n\n### 348. Himalaya, B (64.5)\n\nHimalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents. One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.\n\n- Page: https://www.anchorterminal.com/tools/himalaya · Markdown: https://www.anchorterminal.com/tools/himalaya.md · JSON: https://www.anchorterminal.com/api/v1/tools/himalaya.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts\n\n### 581. Unipile, C (58.4)\n\nUnipile is a hosted API from Unipile SAS in France that connects to accounts people already have. It reads, searches, sends and files mail in Gmail, Outlook and IMAP mailboxes, and also covers calendars, LinkedIn, WhatsApp, Instagram and Telegram. One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.\n\n- Page: https://www.anchorterminal.com/tools/unipile · Markdown: https://www.anchorterminal.com/tools/unipile.md · JSON: https://www.anchorterminal.com/api/v1/tools/unipile.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, calendar.read, calendar.write, calendar.webhooks, messaging.whatsapp, messaging.inbound · endpoint: `https://developer.unipile.com/mcp?branch=v1.0`\n\n### 694. Fastmail API (JMAP), C (54.1)\n\nFastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server. A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.\n\n- Page: https://www.anchorterminal.com/tools/fastmail · Markdown: https://www.anchorterminal.com/tools/fastmail.md · JSON: https://www.anchorterminal.com/api/v1/tools/fastmail.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync\n\n### 702. Zoho Mail API, D (53.8)\n\nZoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access. A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.\n\n- Page: https://www.anchorterminal.com/tools/zoho-mail · Markdown: https://www.anchorterminal.com/tools/zoho-mail.md · JSON: https://www.anchorterminal.com/api/v1/tools/zoho-mail.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync\n\n### 878. Aurinko Email API, E (44.2)\n\nUnified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks. One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.\n\n- Page: https://www.anchorterminal.com/tools/aurinko-email · Markdown: https://www.anchorterminal.com/tools/aurinko-email.md · JSON: https://www.anchorterminal.com/api/v1/tools/aurinko-email.json\n- Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads · endpoint: `https://api.aurinko.io`\n\n## How we test this category\n\nOne test mailbox with the same two hundred messages on each provider. The same tasks run through each listing's API (search, read a thread, write a draft reply, send, label and archive, receive a new-mail event). We check scopes, sync delay and limits. In this run listings are graded from public evidence against the published checklist. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Mailbox access",
        "url": ""
      }
    ],
    "description": "9 mailbox access ranked by the Anchor benchmark. Leader Nylas Email API (A). APIs that let an agent work in a mailbox a person already has. Searching and reading mail, writing drafts, sending and filing. The mailbox providers' own APIs and services that put one API over several providers. Compared on scopes, search, sync and send limits.",
    "facts": [
      "Nylas Email API A",
      "Gmail API BB",
      "EmailEngine BB"
    ],
    "h1": "Mailbox access APIs for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-mailbox-access.png",
    "path": "/categories/mailbox-access",
    "published": "",
    "section": "tools",
    "title": "Mailbox access APIs for AI agents, ranked | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/categories/mailbox-access"
  },
  "tokens": {
    "markdown": 3100,
    "slim": 480
  },
  "version": 1
}
